Looks like the attacker set "legal@google.com" as expeditor name, so that's what showed on the author's phone, that's it.
The headers uploaded are the report email being sent to Google, not the original incoming email. We still don't know how this was spoofed.
minimal efforts, won't pass any scrutinity but someone panicking might miss it.
Thanks OP for the thread, very enlightening.
I wonder how many people would fall for that though.